TITLE OF THE INVENTION 
CRYPTOSYSTEM-RELATED METHOD AND APPARATUS 
BACKGROUND OF THE INVENTION 
Field of the Invention 
5 This invention relates to a method of generating key 

information. Also, this invention relates to an apparatus for 
generating key information. In addition, this invention relates to a 
method of encrypting contents information. Furthermore, this 
invention relates to an apparatus for encrypting contents 
1 0 information. Also, this invention relates to a method of decrypting 
contents information. In addition, this invention relates to an 
apparatus for decrypting contents information. Furthermore, this 
invention relates to a recording medium. Also, this invention 
relates to a method of transmitting contents information. 

1 5 Description of the Related Art 

In a known system for protecting the copyright of digital 
contents information, a provider side encrypts the digital contents 
information in response to an encryption key. In some cases, the 
encryption-resultant contents information is recorded on a 

2 0 recording medium such as a magnetic tape, a magnetic disc, an 

optical disc, or a memory card. In other cases, the encryption- 
resultant contents information is transmitted through a 
communication network. A user side of the known system receives 
the encryption-resultant contents information from the recording 
2 5 medium or the communication network. The user side decrypts 
the encryption-resultant contents information into the original 



contents information in response to a decryption key equivalent to 
the encryption key. 

A conventional DES (Data Encryption Standard) system 
encrypts every 64-bit block of an input data into a 64-bit 

5 encryption-resultant block in response to a 64-bit encryption key. 
Since 8 bits among the 64 bits are used for parities, the encryption 
key has 56 effective bits. The conventional DES system uses an S- 
Box (a Selection-Box) which outputs a 4-bit data piece in response 
to every 6-bit input data piece according to a one-way hash function. 

0 Thus, the S-Box implements data compression. The S-Box in the 
conventional DES system lacks flexibility regarding a data 
compression rate. 

SUMMARY OF THE INVENTION 
It is a first object of this invention to provide an improved 
5 method of generating key information. 

It is a second object of this invention to provide an improved 
apparatus for generating key information. 

It is a third object of this invention to provide an improved 
method of encrypting contents information. 
>0 It is a fourth object of this invention to provide an improved 

apparatus for encrypting contents information. 

It is a fifth object of this invention to provide an improved 
method of decrypting contents information. 

It is a sixth object of this invention to provide an improved 
2 5 apparatus for decrypting contents information. 

It is a seventh object of this invention to provide an improved 



recording medium. 

It is an eighth object of this invention to provide an improved 
method of transmitting contents information. 

A first aspect of this invention provides a method of 
generating key information. The method comprises the steps of 
rearranging bits of a first bit sequence in a first matrix according to 
a predetermined arrangement rule, the first bit sequence 
representing information being a base of a key; forming blocks in 
the first matrix, wherein each of the blocks has bits, the number of 
which is smaller than the number of bits composing the first matrix; 
executing logical operation among bits in each of the blocks and 
generating a bit being a result of the logical operation; combining 
the logical-operation-result bits into a second bit sequence, wherein 
the number of bits composing the second bit sequence is smaller 
than the number of bits composing the first bit sequence; and 
accessing a second matrix composed of predetermined third bit 
sequences and reading out one from among the third bit sequences 
in response to the second bit sequence, and outputting the read-out 
third bit sequence as information representative of the key, wherein 
the number of bits composing each of the third bit sequences is 
smaller than the number of bits composing the second bit sequence. 

A second aspect of this invention provides an apparatus for 
generating key information. The apparatus comprises means for 
rearranging bits of a first bit sequence in a first matrix according to 
a predetermined arrangement rule, the first bit sequence 
representing information being a base of a key; means for forming 



blocks in the first matrix, wherein each of the blocks has bits, the 
number of which is smaller than the number of bits composing the 
first matrix; means for executing logical operation among bits in 
each of the blocks and generating a bit being a result of the logical 
operation; means for combining the logical-operation-result bits into 
a second bit sequence, wherein the number of bits composing the 
second bit sequence is smaller than the number of bits composing 
the first bit sequence; and means for accessing a second matrix 
composed of predetermined third bit sequences and reading out 
one from among the third bit sequences in response to the second 
bit sequence, and outputting the read-out third bit sequence as 
information representative of the key, wherein the number of bits 
composing each of the third bit sequences is smaller than the 
number of bits composing the second bit sequence. 

A third aspect of this invention provides a method of 
encrypting contents information. The method comprises the steps 
of generating a signal representative of a key from information being 
a base of the key, the key base information including a first bit 
sequence; and encrypting contents information in response to the 
key signal. The generating step comprises 1) rearranging bits of the 
first bit sequence in a first matrix according to a predetermined 
arrangement rule; 2) forming blocks in the first matrix, wherein 
each of the blocks has bits, the number of which is smaller than the 
number of bits composing the first matrix; 3) executing logical 
operation among bits in each of the blocks and generating a bit 
being a result of the logical operation; 4) combining the logical- 
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operation-result bits into a second bit sequence, wherein the 
number of bits composing the second bit sequence is smaller than 
the number of bits composing the first bit sequence; and 5) 
accessing a second matrix composed of predetermined third bit 
5 sequences and reading out one from among the third bit sequences 
in response to the second bit sequence, and outputting the read-out 
third bit sequence as the key signal, wherein the number of bits 
composing each of the third bit sequences is smaller than the 
number of bits composing the second bit sequence. 
10 A fourth aspect of this invention provides an apparatus for 

encrypting contents information. The apparatus comprises means 
for generating a signal representative of a key from information 
being a base of the key, the key base information including a first bit 
sequence; and means for encrypting contents information in 

1 5 response to the key signal. The generating means comprises 1) 

means for rearranging bits of the first bit sequence in a first matrix 
according to a predetermined arrangement rule; 2) means for 
forming blocks in the first matrix, wherein each of the blocks has 
bits, the number of which is smaller than the number of bits 

2 0 composing the first matrix; 3) means for executing logical operation 

among bits in each of the blocks and generating a bit being a result 
of the logical operation; 4) means for combining the logical- 
operation-result bits into a second bit sequence, wherein the 
number of bits composing the second bit sequence is smaller than 
2 5 the number of bits composing the first bit sequence; and 5) means 
for accessing a second matrix composed of predetermined third bit 



sequences and reading out one from among the third bit sequences 
in response to the second bit sequence, and outputting the read-out 
third bit sequence as the key signal, wherein the number of bits 
composing each of the third bit sequences is smaller than the 
number of bits composing the second bit sequence. 

A fifth aspect of this invention provides a method of 
decrypting contents information. The method comprises the steps 
of generating a signal representative of a key from information being 
a base of the key, the key base information including a first bit 
sequence; and decrypting encryption-resultant contents information 
in response to the key signal. The generating step comprises 1) 
rearranging bits of the first bit sequence in a first matrix according 
to a predetermined arrangement rule; 2) forming blocks in the first 
matrix, wherein each of the blocks has bits, the number of which is 
smaller than the number of bits composing the first matrix; 3) 
executing logical operation among bits in each of the blocks and 
generating a bit being a result of the logical operation; 4) combining 
the logical-operation-result bits into a second bit sequence, wherein 
the number of bits composing the second bit sequence is smaller 
than the number of bits composing the first bit sequence; and 5) 
accessing a second matrix composed of predetermined third bit 
sequences and reading out one from among the third bit sequences 
in response to the second bit sequence, and outputting the read-out 
third bit sequence as the key signal, wherein the number of bits 
composing each of the third bit sequences is smaller than the 
number of bits composing the second bit sequence. 



A sixth aspect of this invention provides an apparatus for 
decrypting contents information. The apparatus comprises means 
for generating a signal representative of a key from information 
being a base of the key, the key base information including a first bit 
sequence; and means for decrypting encryption-resultant contents 
information in response to the key signal. The generating means 
comprises 1) means for rearranging bits of the first bit sequence in 
a first matrix according to a predetermined arrangement rule; 2) 
means for forming blocks in the first matrix, wherein each of the 
blocks has bits, the number of which is smaller than the number of 
bits composing the first matrix; 3) means for executing logical 
operation among bits in each of the blocks and generating a bit 
being a result of the logical operation; 4) means for combining the 
logical-operation-result bits into a second bit sequence, wherein the 
number of bits composing the second bit sequence is smaller than 
the number of bits composing the first bit sequence; and 5) means 
for accessing a second matrix composed of predetermined third bit 
sequences and reading out one from among the third bit sequences 
in response to the second bit sequence, and outputting the read-out 
third bit sequence as the key signal, wherein the number of bits 
composing each of the third bit sequences is smaller than the 
number of bits composing the second bit sequence. 

A seventh aspect of this invention provides a recording 
medium storing encryption-resultant key base information and 
encryption-resultant contents information generated by the method 
in the third aspect of this invention. 



An eighth aspect of this invention provides a method of 
transmitting contents information. The method comprises the 
steps of transmitting encryption-resultant key base information 
through a transmission line, and transmitting encryption-resultant 
contents information through the transmission line, the encryption- 
resultant contents information being generated by the method in 
the third aspect of this invention. 

A ninth aspect of this invention provides a method of 
generating key information. The method comprises the steps of 
dividing a first bit sequence into second bit sequences, the first bit 
sequence being contained in information being a base of a key, 
wherein the number of bits composing each of the second bit 
sequences is smaller than the number of bits composing the first bit 
sequence; sequentially accessing a first matrix composed of 
predetermined data pieces and sequentially reading out ones from 
among the predetermined data pieces in response to the second bit 
sequences; combining the read- out data pieces into a third bit 
sequence, wherein the number of bits composing the third bit 
sequence is smaller than the number of bits composing the first bit 
sequence; rearranging bits of at least part of the third bit sequence 
in a second matrix according to a predetermined arrangement rule; 
forming blocks in the second matrix, wherein each of the blocks has 
bits, the number of which is smaller than the number of bits 
composing the second matrix; executing logical operation among 
bits in each of the blocks and generating a bit being a result of the 
logical operation; and combining the logical-operation-result bits 



into a fourth bit sequence, and outputting the fourth bit sequence as 
at least part of information representative of the key, wherein the 
number of bits composing the fourth bit sequence is smaller than 
the number of bits composing the second matrix. 

A tenth aspect of this invention provides an apparatus for 
generating key information. The apparatus comprises means for 
dividing a first bit sequence into second bit sequences, the first bit 
sequence being contained in information being a base of a key, 
wherein the number of bits composing each of the second bit 
sequences is smaller than the number of bits composing the first bit 
sequence; means for sequentially accessing a first matrix composed 
of predetermined data pieces and sequentially reading out ones 
from among the predetermined data pieces in response to the 
second bit sequences; means for combining the read-out data pieces 
into a third bit sequence, wherein the number of bits composing the 
third bit sequence is smaller than the number of bits composing the 
first bit sequence; means for rearranging bits of at least part of the 
third bit sequence in a second matrix according to a predetermined 
arrangement rule; means for forming blocks in the second matrix, 
wherein each of the blocks has bits, the number of which is smaller 
than the number of bits composing the second matrix; means for 
executing logical operation among bits in each of the blocks and 
generating a bit being a result of the logical operation; and means 
for combining the logical-operation-result bits into a fourth bit 
sequence, and outputting the fourth bit sequence as at least part of 
information representative of the key, wherein the number of bits 
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composing the fourth bit sequence is smaller than the number of 
bits composing the second matrix. 

An eleventh aspect of this invention provides a method of 
encrypting contents information. The method comprises the steps 
of generating a signal representative of a key from information being 
a base of the key, the key base information including a first bit 
sequence; and encrypting contents information in response to the 
key signal. The generating step comprises 1) dividing the first bit 
sequence into second bit sequences, wherein the number of bits 
composing each of the second bit sequences is smaller than the 
number of bits composing the first bit sequence; 2) sequentially 
accessing a first matrix composed of predetermined data pieces and 
sequentially reading out ones from among the predetermined data 
pieces in response to the second bit sequences; 3) combining the 
read-out data pieces into a third bit sequence, wherein the number 
of bits composing the third bit sequence is smaller than the number 
of bits composing the first bit sequence; 4) rearranging bits of at 
least part of the third bit sequence in a second matrix according to 
a predetermined arrangement rule; 5) forming blocks in the second 
matrix, wherein each of the blocks has bits, the number of which is 
smaller than the number of bits composing the second matrix; 6) 
executing logical operation among bits in each of the blocks and 
generating a bit being a result of the logical operation; and 7) 
combining the logical-operation-result bits into a fourth bit 
sequence, and outputting the fourth bit sequence as at least part of 
the key signal. 
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A twelfth aspect of this invention provides an apparatus for 
encrypting contents information. The apparatus comprises means 
for generating a signal representative of a key from information 
being a base of the key, the key base information including a first bit 
sequence; and means for encrypting contents information in 
response to the key signal. The generating means comprises 1) 
means for dividing the first bit sequence into second bit sequences, 
wherein the number of bits composing each of the second bit 
sequences is smaller than the number of bits composing the first bit 
sequence; 2) means for sequentially accessing a first matrix 
composed of predetermined data pieces and sequentially reading 
out ones from among the predetermined data pieces in response to 
the second bit sequences; 3) means for combining the read-out data 
pieces into a third bit sequence, wherein the number of bits 
composing the third bit sequence is smaller than the number of bits 
composing the first bit sequence; 4) means for rearranging bits of at 
least part of the third bit sequence in a second matrix according to 
a predetermined arrangement rule; 5) means for forming blocks in 
the second matrix, wherein each of the blocks has bits, the number 
of which is smaller than the number of bits composing the second 
matrix; 6) means for executing logical operation among bits in each 
of the blocks and generating a bit being a result of the logical 
operation; and 7) means for combining the logical-operation-result 
bits into a fourth bit sequence, and outputting the fourth bit 
sequence as at least part of the key signal. 

A thirteenth aspect of this invention provides a method of 
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deciypting contents information. The method comprises the steps 
of generating a signal representative of a key from information being 
a base of the key, the key base information including a first bit 
sequence; and decrypting encryption-resultant contents information 
in response to the key signal. The generating step comprises 1) 
dividing the first bit sequence into second bit sequences, wherein 
the number of bits composing each of the second bit sequences is 
smaller than the number of bits composing the first bit sequence; 2) 
sequentially accessing a first matrix composed of predetermined 
data pieces and sequentially reading out ones from among the 
predetermined data pieces in response to the second bit sequences; 
3) combining the read-out data pieces into a third bit sequence, 
wherein the number of bits composing the third bit sequence is 
smaller than the number of bits composing the first bit sequence; 4) 
rearranging bits of at least part of the third bit sequence in a second 
matrix according to a predetermined arrangement rule; 5) forming 
blocks in the second matrix, wherein each of the blocks has bits, 
the number of which is smaller than the number of bits composing 
the second matrix; 6) executing logical operation among bits in each 
of the blocks and generating a bit being a result of the logical 
operation; and 7) combining the logical-operation-result bits into a 
fourth bit sequence, and outputting the fourth bit sequence as at 
least part of the key signal. 

A fourteenth aspect of this invention provides an apparatus for 
decrypting contents information. The apparatus comprises means 
for generating a signal representative of a key from information 
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being a base of the key, the key base information including a first bit 
sequence; and means for decrypting encryption-resultant contents 
information in response to the key signal. The generating means 
comprises 1) means for dividing the first bit sequence into second 
bit sequences, wherein the number of bits composing each of the 
second bit sequences is smaller than the number of bits composing 
the first bit sequence; 2) means for sequentially accessing a first 
matrix composed of predetermined data pieces and sequentially 
reading out ones from among the predetermined data pieces in 
response to the second bit sequences; 3) means for combining the 
read-out data pieces into a third bit sequence, wherein the number 
of bits composing the third bit sequence is smaller than the number 
of bits composing the first bit sequence; 4) means for rearranging 
bits of at least part of the third bit sequence in a second matrix 
according to a predetermined arrangement rule; 5) means for 
forming blocks in the second matrix, wherein each of the blocks has 
bits, the number of which is smaller than the number of bits 
composing the second matrix; 6} means for executing logical 
operation among bits in each of the blocks and generating a bit 
being a result of the logical operation; and 7) means for combining 
the logical- operation-result bits into a fourth bit sequence, and 
outputting the fourth bit sequence as at least part of the key signal. 

A fifteenth aspect of this invention provides a recording 
medium storing encryption-resultant key base information and 
encryption-resultant contents information generated by the method 
in the eleventh aspect of this invention. 
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A sixteenth aspect of this invention provides a method of 
transmitting contents information. The method comprises the 
steps of transmitting encryption-resultant key base information 
through a transmission line, and transmitting encryption-resultant 
contents information through the transmission line, the encryption- 
resultant contents information being generated by the method in 
the eleventh aspect of this invention. 

BRIEF DESCRIPTION OF THE DRAWINGS 

Fig. 1 is a diagram of a prior-art S-Box. 

Fig. 2 is a block diagram of a system for contents information 
according to a first embodiment of this invention. 

Fig. 3 is a flow diagram of operation of a calculator (a key 
generator) in Fig. 2. 

Fig. 4 is a block diagram of the calculator in Fig. 2. 
Fig. 5 is a block diagram of a system for contents information 
according to a second embodiment of this invention. 

Fig. 6 is a flow diagram of operation of a calculator (a key 
generator) in Fig. 5. 

Fig. 7 is a block diagram of the calculator in Fig. 5. 

DESCRIPTION OF THE PREFERRED EMBODIMENTS 
A prior-art S-Box will be explained below for a better 
understanding of this invention. 

Fig. 1 shows an S-Box 50 in a prior-art DES system. The S- 
Box 50 outputs a 4-bit data piece in response to every 6-bit input 
data piece according to a one-way hash function "F(x)". Thus, the S- 
Box 50 implements data compression. The 6 bits in every input 
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data piece are denoted by b$, bq., b$, b2, b\, and bQ, respectively. 

The one-way hash function is designed to meet the following 
conditions. It is easy to calculate the value "F(x)" from the value "x". 
It is difficult to calculate the value "x" from the value "F(x)". 
5 The S-Box 50 includes a memory 50T storing data 

representing a two-dimensional table being a matrix of 
predetermined 4-bit data pieces. Specifically, the matrix has 4 
rows by 16 columns. Four different states of a 2-bit signal are 
assigned to the rows in the matrix, respectively. Sixteen different 

1 0 states of a 4-bit signal are assigned to the columns in the matrix, 

respectively. 

The S-Box 50 separates the 6 bits of every input data piece 
into first and second groups. The first group has bits b5 and bQ. 
The second group has bits b4, b3, b2, and b\. The first group (bits 
15 bs and bo) is used as a 2-bit signal for designating one from among 
the rows in the matrix. The second group (bits 04, b3, b2, and bi) 
is used as a 4-bit signal for designating one from among the columns 
in the matrix. A 4-bit predetermined data piece is read out from an 
element position in the matrix which coincides with the 

2 0 intersection of the designated row and column. The S-Box 50 

outputs the read-out 4-bit data piece. 

For example, an input data piece being "100100" is separated 
into a 2-bit signal of "10" (bits bs and bo) and a 4-bit signal of 
"0010" (bits b4, b3, b2> and bi). The 2-bit signal of "10" designates 
2 5 corresponding one of the rows in the matrix. The 4-bit signal of 

"0010" designates corresponding one of the columns in the matrix. 
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A predetermined 4-bit data piece being "1001" resides in an 
element position in the matrix which coincides with the 
intersection of the designated row and column. Thus, the 4-bit data 
piece "1001" is read out from the matrix before being outputted 
from the S-Box 50. 

The S-Box 50 in the prior-art DES system is able to 
implement only 6-to-4 bit data reduction (compression). 
Accordingly, the S-Box 50 lacks flexibility regarding a data 
compression rate. 

First Embodiment 

Fig. 2 shows a system for contents information according to a 
first embodiment of this invention. The system of Fig. 2 includes a 
primary section P, a secondary section Q, and an intermediate 
section R. The primary section P and the secondary section Q are 
connected to each other via the intermediate section R. 

The primary section P includes an information recording 
apparatus or an information transmitting apparatus. The secondary 
section Q includes an information reproducing apparatus or an 
information receiving apparatus. An example of the information 
reproducing apparatus is an information player. The intermediate 
section R includes a recording medium or a transmission medium. 
Examples of the recording medium are a magnetic tape, a magnetic 
disc, an optical disc, and a memory card. Examples of the 
transmission medium are a communication network, a radio 
transmission line, and an optical transmission line. The 
communication network is, for example, the Internet or a telephone 
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network. The transmission medium is also referred to as a 
transmission line. 

The primary section P includes an encryptor 2, a calculator or 
a key generator 3, and an encryptor 5. The calculator 3 receives 
5 information being a base of a first key Kl. The first-key base 
information is fed from a suitable device (not shown). The 
calculator 3 generates a signal (data) representative of the first key 
Kl from the first-key base information according to a 
predetermined one-way hash function. The calculator 3 outputs the 
1 0 first-key signal (the first-key data) to the encryptor 5. Preferably, 
the number of bits composing the first-key signal is significantly 
smaller than that of bits composing the first-key base information. 

The encryptor 5 receives digital contents information from a 
suitable device (not shown). The contents information includes a 

1 5 video signal, an audio signal, or an audio video signal representing 

copyrighted contents. The encryptor 5 encrypts the received 
contents information into encryption-resultant contents information 
in response to the first-key signal. The encryptor 5 outputs the 
encryption-resultant contents information to the intermediate 

2 0 section R. 

Specifically, the primary section P records the encryption- 
resultant contents information on the recording medium of the 
intermediate section R, or transmits the encryption-resultant 
contents information to the transmission line of the intermediate 
2 5 section R. 

A signal (data) representative of a second key K2 is available in 
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the primary section P. The second-key signal is fed from a suitable 
device (not shown). The second key K2 is peculiar to the system. 
Thus, the second key K2 is also referred to as the system key K2. 
For example, the second key K2 is based on identification (ID) 
information of the system. The second key K2 differs from the first 
key Kl. The second key K2 may be equal to the first key Kl. 

The encryptor 2 receives the first-key base information and 
also the second-key signal. The encryptor 2 encrypts the first-key 
base information into encryption-resultant first-key base information 
in response to the second-key signal. The encryptor 2 outputs the 
encryption-resultant first-key base information to the intermediate 
section R. 

Specifically, the primary section P records the encryption- 
resultant first-key base information on the recording medium of the 
intermediate section R, or transmits the encryption-resultant first- 
key base information to the transmission line of the intermediate 
section R. 

The encryption-resultant contents information and the 
encryption-resultant first-key base information are transmitted from 
the primary section P to the secondary section Q through the 
intermediate section R. 

The secondary section Q includes a decrypting device 8, a 
calculator or a key generator 10, and a decrypting device 11. A 
signal (data) representative of a second key or a system key K2 is 
available in the secondary section Q. The second-key signal is fed 
from a suitable device (not shown). The second key K2 is peculiar 
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to the system. For example, the second key K2 is based on 
identification (ID) information of the system. The second key K2 in 
the secondary section Q is equivalent to that in the primary section 
P. 

5 The decrypting device 8 receives the second-key signal. In 

addition, the decrypting device 8 receives the encryption-resultant 
first-key base information from the intermediate section R. The 
decrypting device 8 decrypts the encryption-resultant first-key base 
information into the first-key base information in response to the 
1 0 second-key signal. The decrypting device 8 outputs the first-key 
base information to the calculator 10. 

The calculator 10 generates a signal (data) representative of a 
first key Kl from the first-key base information according to a 
predetermined one-way hash function equal to that used by the 

1 5 calculator 3 in the primary section P. The calculator 10 outputs the 

first-key signal (the first-key data) to the decrypting device 1 1 . The 
first key Kl generated by the calculator 10 is equivalent to that 
generated by the calculator 3 in the primary section P. 

The decrypting device 11 receives the encryption-resultant 

2 0 contents information from the intermediate section R. The 

decrypting device 11 decrypts the encryption-resultant contents 
information into the original digital contents information in 
response to the first-key signal. Thus, the decrypting device 1 1 
reproduces the original digital contents information. The 
2 5 decrypting device 11 outputs the reproduced digital contents 
information. 
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The second key (the system key) K2 in the primary section P 
and that in the secondary section Q may be based on a common key 
cryptosystem. In this case, both the primary section P and the 
secondary section Q use a common key as a system key K2. The 
5 second key (the system key) K2 in the primary section P and that in 
the secondary section Q may be based on a public-key cryptosystem 
or a key- delivery cryptosystem. 

The calculator (the key generator) 3 in the primary section P 
and the calculator (the key generator) 10 in the secondary section Q 
1 0 are similar in design and operation. Therefore, only the calculator 3 
will be explained in more detail. 

Fig. 3 shows a flow of operation of the calculator 3. Fig. 4 
shows a structure of the calculator 3. As shown in Fig. 3, the flow of 
operation of the calculator 3 is divided into first and second steps. 

1 5 The second step follows the first step. The operation of the 

calculator 3 accords with the predetermined one-way hash function. 
As shown in Fig. 4, the calculator 3 includes a logical operation unit 
21 and an S-Box (a Selection-Box) 22 connected to each other. The 
S-Box 22 is designed in conformity with DES (Data Encryption 

2 0 Standard). 

With reference to Figs. 3 and 4, the calculator 3 receives the 
first-key base information. In the first step of Fig. 3, the logical 
operation unit 21 divides the first-key base information into blocks 
each having 25 successive bits. Each of the blocks forms a first bit 
2 5 sequence, that is, a sequence of bits an, a\2, a l3> a l4> a l5> a 21> 

a 22- a 23> a 24> a 25> a 31* a 32> a 33- a 34> a 35- a 41> a 42> ^3- a 44> a 45' 



-21 - 



a 51> a 52> a 53' a 54- a^d a 55- Tne ^d second steps of Fig. 3 
execute block-by-block signal processing. 

In the first step of Fig. 3, the logical operation unit 21 
rearranges the bits of each first bit sequence in a first matrix Ml 
5 according to a predetermined arrangement rule equal to that used 
in the calculator 10 of the secondary side Q. The first matrix Ml 
has 5 rows by 5 columns. Specifically, the first row in the first 
matrix Ml has bits aji, &\2> a 13> a 14> a^d a 15- Tne second row 
has bits a.21, &22> a 23- a 24> an d ^25. The third row has bits a.31 , 
1 0 a32, a33, a34, and a35- The fourth row has bits , 3.4.2, a 43> a 44> 
and a45- The fifth row has bits a52> a.53, a54, and a.55. The 

first column in the first matrix Ml has bits ai i, a2i, a-31> a 41> an d 
asi . The second column has bits ai 2. a-22» a 32» a 42> an< ^ a 52- The 
third column has bits an 3, a23, a33, a43, and a53- The fourth 

1 5 column has bits ai4, a24> a34, a44, and a54- The fifth column has 

bits ai 5, a 2 5. a 35- a 45> ^d a 55- 

In the first step of Fig. 3, the logical operation unit 21 sets a 
movable scanning window in the first matrix Ml which covers 2-by- 
2 neighboring elements (bits). Initially, the window is located in 
20 the uppermost and leftmost position within the first matrix Ml, 

covering bits ax2» a 21> a^d a 22- Tne logical operation unit 21 

executes Exclusive- OR operation among the bits an, ai2> a 21> a^d 
a22- The result of the Exclusive-OR operation is a bit b]_ 1. The 
logical operation unit 2 1 places the bit b \ \ in the first-row first- 

2 5 column element position within a second matrix M2. As will be 

made clear later, the second matrix M2 has 4 rows by 4 columns. 
The window is shifted rightward from the initial position by one 
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column. The resultant window covers bits ai 2, ai 3, a 22> an d a 23- 
The logical operation unit 21 executes Exclusive-OR operation 
among the bits a 12, a 13, a22> ^d a 23- Tne result of the Exclusive- 
OR operation is a bit bi 2- The logical operation unit 21 places the 
5 bit bi2 in tb_ e first-row second-column element position within the 
second matrix M2. During a subsequent stage, signal processing 
similar to the above-mentioned signal processing is iterated. 
Specifically, the window is shifted rightward one column by one 
column, and Exclusive-OR operation is executed among four bits in 
1 0 the window each time the window is in one position. A bit being 
the result of each Exclusive-OR operation is placed in a 
corresponding element position within the second matrix M2. The 
window reaches the uppermost and rightmost position. When 
signal processing related to the window in the uppermost and 

1 5 rightmost position is completed, the first row in the second matrix 

M2 is filled with bits bn, bi2> b 13> and D 14- 

Then, the window is shifted to the second-uppermost and 
leftmost position within the first matrix Ml, covering bits a2i, a22> 
a3i , and a32- The logical operation unit 21 executes Exclusive-OR 

2 0 operation among the bits a2i> a22> a 31> a 32- Tne result of the 

Exclusive-OR operation is a bit b2i- The logical operation unit 21 
places the bit b2 1 in the second-row first-column element position 
within the second matrix M2. The window is shifted rightward by 
one column. The resultant window covers bits a22> a 23- a 32> 
2 5 a33. The logical operation unit 21 executes Exclusive-OR operation 
among the bits a22> a 23- a 32» a 33- Tne result of the Exclusive- 
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OR operation is a bit b22- The logical operation unit 21 places the 
bit b22 in the second-row second-column element position within 
the second matrix M2. During a subsequent stage, signal processing 
similar to the above-mentioned signal processing is iterated. 
5 Specifically, the window is shifted rightward one column by one 
column, and Exclusive-OR operation is executed among four bits in 
the window each time the window is in one position. A bit being 
the result of each Exclusive-OR operation is placed in a 
corresponding element position within the second matrix M2. The 

1 0 window reaches the second-uppermost and rightmost position. 

When signal processing related to the window in the second- 
uppermost and rightmost position is completed, the second row in 
the second matrix M2 is filled with bits b2i, b22' b23> and b24- 
Then, the window is shifted to the third-uppermost and 
15 leftmost position within the first matrix Ml. During a subsequent 
stage, signal processing similar to the above-mentioned signal 
processing is iterated. Specifically, the window is shifted rightward 
one column by one column, and Exclusive-OR operation is executed 
among four bits in the window each time the window is in one 

2 0 position. A bit being the result of each Exclusive-OR operation is 

placed in a corresponding element position within the second 
matrix M2. Finally, the window reaches the lowermost and 
rightmost position. When signal processing related to the window 
in the lowermost and rightmost position is completed, the second 
25 matrix M2 is filled with bits bii, bi2' b 13- b 14« b 21> b 22> b 23> b 24> 
D 31> D 32> D 33» D 34> b 41» b 42> D 43> D 44- m ^ s wa Y' ^ first 



-24- 



step of Fig. 3 compresses the first matrix Ml into the second matrix 
M2. In other words, the first step compresses 25 bits (one block) 
into 16 bits. In the first step of Fig. 3, the logical operation unit 21 
rearranges the bits of the second matrix M2 into a second bit 
5 sequence, that is, a sequence of bits b^, b\2> bl3> bi 4 , b2i, b22> 
b 23> b 24' b 31> b 32> b 33' b3 4 , b 4 i, b 4 2, b 4 3, and b 44 . 

Each Exclusive-OR operation among four bits ay, ay + i , a i+lj. 
and ai + ij + i in the window is generally expressed as follows. 

bij = ay © ay +1 © a i+1 j © a i+1 j + 1 -(1) 
10 i, j = 1, 2, 3, 4 

where bij denotes a bit being the result of the Exclusive-OR 
operation, and © denotes an operator of one unit portion of the 
Exclusive-OR operation. 

Setting the window in the first matrix Ml and shifting the 

1 5 window therein mean forming blocks in the first matrix Ml, 

wherein each of the blocks has bits, the number of which is smaller 
than the number of bits composing the first matrix Ml. Exclusive- 
OR operation among bits in the window means logical operation 
among bits in each of blocks in the first matrix M 1 . 

2 0 It should be noted that the first step may divide the first-key 

base information into blocks each having more than or less than 25 
successive bits. The first step may rearrange the bits of each first 
bit sequence (each 25-bit sequence) in the first matrix Ml 
according to a predetermined arrangement rule different from the 
2 5 previously-mentioned arrangement rule. The first step may execute 
OR operation or AND operation among four bits in the window 
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instead of Exclusive-OR operation. 

The second step of Fig. 3 relates to the S-Box 22. The S-Box 
22 outputs a 4-bit data piece (a 4-bit sequence) in response to every 
8-bit input data piece according to a one-way hash function. Thus, 
5 the S-Box 22 implements data compression. The S-Box 22 includes 
a memory 22T storing data representing a two-dimensional table 
being a matrix (an S-Box matrix) of predetermined 4-bit data pieces 
or predetermined 4-bit sequences. Specifically, the S-Box matrix 
has 16 rows by 16 columns. Sixteen different states of a 4-bit signal 
1 0 are assigned to the rows in the S-Box matrix, respectively. Sixteen 
different states of a 4-bit signal are assigned to the columns in the 
S-Box matrix, respectively. 

In a former half of the second step of Fig. 3, the S-Box 22 
selects 8 bits from the second bit sequence generated by the first 

1 5 step according to a predetermined selection rule equal to that used 

in the calculator 10 of the secondary side Q. Specifically, the S-Box 
22 selects bits bn, bi2> ^13' bi4, b2i, b22* t>23' and b24 from the 
second bit sequence. Then, the S-Box 22 separates the 8 selected 
bits into first and second groups. The first group has bits b]_ ]_ , bx2> 

2 0 bi3, and bi4- The second group has bits b2i, b22» ^>2S> and b24- 

The first group (bits bi x, b^2. t>13' ^d bi4) is used as a 4-bit signal 
for designating one from among the rows in the S-Box matrix. The 
second group (bits b2i, b22. b 23» D 24) is used as a 4-bit signal 
for designating one from among the columns in the S-Box matrix. A 
2 5 predetermined 4-bit data piece (a predetermined 4-bit sequence) is 
read out from an element position in the S-Box matrix which 
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coincides with the intersection of the designated row and column. 
The S-Box 22 outputs the read-out 4-bit data piece as a 4-bit portion 
of the first-key signal (the signal representative of the first key Kl). 
In a latter half of the second step of Fig. 3, the S-Box 22 
5 selects 8 remaining bits, that is, bits b3i, b32, b33, b34, b.41, b42, 
b43, and b44 from the second bit sequence generated by the first 
step. Then, the S-Box 22 separates the 8 selected bits into first and 
second groups. The first group has bits b^i, b32, b33, and b34- 
The second group has bits b4i, b42, b43, and b44- The first group 

1 0 (bits b3i, b32, t>33> and b34) is used as a 4-bit signal for designating 

one from among the rows in the S-Box matrix. The second group 
(bits b4i, b42, b43, and b44) is used as a 4-bit signal for designating 
one from among the columns in the S-Box matrix. A predetermined 
4-bit data piece (a predetermined 4-bit sequence) is read out from 
15 an element position in the S-Box matrix which coincides with the 
intersection of the designated row and column. The S-Box 22 
outputs the read-out 4-bit data piece as another 4-bit portion of the 
first-key signal (the signal representative of the first key Kl). In 
this way, the second step of Fig. 3 compresses the second bit 

2 0 sequence (the 16-bit sequence) into an 8-bit portion of the first- key 

signal. Repetition of the previously-mentioned signal processing in 
the first and second steps of Fig. 3 completes the first-key signal. 

It should be noted that the S-Box matrix for the bits b3i, b32, 
D 33> t>34, t>4i, t>42, D 43- and b44 may differ from the S-Box matrix 
2 5 for the bits b^, bi2- b 13> b 14> b 21> b 22- b 23« b 24- Each of the 
data pieces at the respective element positions in the S-Box matrix 
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may have a predetermined number of bits which differs from 4. 

As understood from the previous description, the calculators 
or the key generators 3 and 10 implement 25-to-16 bit data 
reduction (compression) in the first step, and implement 16-to-8 
5 bit data reduction (compression) in the second step. The S-Box 22 
may fail to process bits D31, b^2> ^33, b34, b4i , b42, b43, and b44 
in the second bit sequence. In this case, the calculators 3 and 10 
implement 16-to-4 bit data reduction (compression) in the second 
step. The calculators 3 and 10 may process and compress selected 
1 0 one or ones of 25-bit blocks of the first-key base information. In 
this case, the rate of the compression of the first-key base 
information to generate the first-key signal can be changed among 
different values. The first-key base information may have a given 
number of bits which differs from a multiple of 25. In this case, the 

1 5 calculators 3 and 10 divide the first-key base information into 25-bit 

blocks and one remaining block having bits, the number of which 
differs from 25. The calculators 3 and 10 discard the remaining 
block. Accordingly, the rate of the compression of the first-key base 
information to generate the first-key signal can be changed among 

2 0 various values. Thus, the calculators 3 and 10 are sufficiently 

flexible regarding a data compression rate. 

The first embodiment of this invention may be modified as 
follows. Specifically, a modification of the first embodiment of this 
invention implements encryption through "n" stages, where "n" 
2 5 denotes a predetermined natural number equal to or greater than 3. 
In the modification, an n-th encryptor encrypts (n-l)-th key base 
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information according to a predetermined one-way function. 

Second Embodiment 
Fig. 5 shows a system for contents information according to a 
second embodiment of this invention. The system of Fig. 5 is 
5 similar to the system of Fig. 2 except for design changes mentioned 
later. The system of Fig. 5 includes a primary section PA and a 
secondary section QA instead of the primary section P and the 
secondary section Q (see Fig. 2), respectively. 

The primary section PA is similar to the primary section P 
1 0 except that a signal generator (a key generator) 3A replaces the 

signal generator 3 in Fig. 2. The secondary section QA is similar to 
the secondary section Q except that a signal generator (a key 
generator) 10A replaces the signal generator 10 in Fig. 2. 

The calculator (the key generator) 3A in the primary section 

1 5 PA and the calculator (the key generator) 10A in the secondary 

section QA are similar in design and operation. Therefore, only the 
calculator 3A will be explained in more detail. 

Fig. 6 shows a flow of operation of the calculator 3A. Fig. 7 
shows a structure of the calculator 3A. As shown in Fig. 6, the flow 

2 0 of operation of the calculator 3A is divided into first and second 

steps. The second step follows the first step. The operation of the 
calculator 3A accords with a predetermined one-way hash function. 
As shown in Fig. 7, the calculator 3A includes an S-Box (a Selection- 
Box) 31 and a logical operation unit 32 connected to each other. 
2 5 The S-Box 31 is designed in conformity with DES. 

With reference to Figs. 6 and 7, the calculator 3A receives 
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first-key base information forming a first bit sequence, for example, 
a 200-bit sequence. The first and second steps of Fig. 6 
compressively changes the first-key base information into a first-key 
signal (a signal representative of a first key). Preferably, the number 
5 of bits composing the first-key signal is significantly smaller than 
that of bits composing the first-key base information. 

The first step of Fig. 6 relates to the S-Box 31. The S-Box 31 
outputs a 4-bit data piece (a 4-bit sequence) in response to every 8- 
bit input data piece according to a one-way hash function. Thus, the 
1 0 S-Box 31 implements data compression. The S-Box 31 includes a 
memory 3 IT storing data representing a two-dimensional table 
being a matrix (an S-Box matrix) of predetermined 4-bit data pieces 
or predetermined 4-bit sequences. Specifically, the S-Box matrix 
has 16 rows by 16 columns. Sixteen different states of a 4-bit signal 

1 5 are assigned to the rows in the S-Box matrix, respectively. Sixteen 

different states of a 4-bit signal are assigned to the columns in the 
S-Box matrix, respectively. 

In the first step of Fig. 6, the S-Box 31 divides the first-key 
base information into 25 blocks each having 8 successive bits. Each 

2 0 of the 8-bit blocks forms a second bit sequence, that is, a sequence 

of bits ai, a2, a3, a.4, as, ag, ay, and slq. The first step executes 
block-by-block signal processing. 

In the first step of Fig. 6, the S-Box 31 separates the 8 bits of 
first one of the blocks into first and second groups. The first group 
25 has bits ax, &2' a 3> and a 4- The second g rou P nas bits a 5> a 6> a 7> 
and slq. The first group (bits a.\, &2, ^d sl^) is used as a 4-bit 
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signal for designating one from among the rows in the S-Box matrix. 
The second group (bits ag, aj, and ag) is used as a 4-bit signal 
for designating one from among the columns in the S-Box matrix. A 
predetermined 4-bit data piece (a predetermined 4-bit sequence) is 
5 read out from an element position in the S-Box matrix which 

coincides with the intersection of the designated row and column. 
The S-Box 31 outputs the read-out 4-bit data piece as a 4-bit portion 
of a third bit sequence (a 100-bit sequence) which corresponds to 
the first one of the 8-bit blocks. 
1 0 For each of second and later ones of the 8-bit blocks, the S- 

Box 31 executes signal processing similar to the above-mentioned 
signal processing. As a result, the S-Box 31 compresses the 25 8- 
bit blocks into the respective 4-bit portions of the third bit 
sequence (the 100-bit sequence). In other words, the S-Box 31 

1 5 compresses the first bit sequence (the 200-bit sequence) into the 

third bit sequence (the 100-bit sequence). 

It should be noted that the first bit sequence formed by the 
first-key base information may have a predetermined number of bits 
which differs from 200. Also, the second bit sequence may have a 

2 0 predetermined number of bits which differs from 8. Furthermore, 

each of the data pieces at the respective element positions in the S- 
Box matrix may have a predetermined number of bits which differs 
from 4. In addition, the contents of the 4-bit data pieces at the 
respective element positions in the S-Box matrix may vary from 8- 
2 5 bit block to 8-bit block. In this case, different S-Box matrixes are 

provided for the 25 8-bit blocks, respectively. Only selected one or 
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ones of the 4-bit data pieces read out from the S-Box matrix may be 
used to form the third bit sequence. In this case, the number of bits 
composing the third bit sequence differs from 100. 

In the second step of Fig. 6, the logical operation unit 32 
divides the third bit sequence (the 100-bit sequence) generated by 
the first step into blocks each having 25 successive bits. Each of the 
25-bit blocks forms a fourth bit sequence, that is, a sequence of bits 
bn, bi2. bi3, b 14 , bi5, b2i, b 22> b 23. b 24- b 25' b 31> b 32- b 33> 
b 34> b 35> b 41> b 42. b 43> b 44> b 45> b 51> b 52> b 53' b 54* and bss. 
The second step of Fig. 6 executes signal processing on a 25-bit- 
block by 25-bit-block basis. 

When the number of bits composing the third bit sequence is 
equal to 25, the third bit sequence is directly used as the fourth bit 
sequence. 

In the second step of Fig. 6, the logical operation unit 32 uses 
a first matrix Ml and a second matrix M2. Specifically, the logical 
operation unit 32 rearranges the bits of each fourth bit sequence in 
the first matrix Ml according to a predetermined arrangement rule 
equal to that used in the calculator 10A of the secondary side QA. 
The first matrix Ml has 5 rows by 5 columns. Specifically, the first 
row in the first matrix Ml has bits bn, bi2, bi3, bi4, and bi5- 
The second row has bits b2i, b22» b 23> b 24> and b 25- Tne third 
row has bits b3i, b32» b33, b34, and b35< The fourth row has bits 

b 41' b 42- b 43> b 44- and b 45- The fifth row has bits b 51- b 52> b 53> 
b54, and b55- The first column in the first matrix Ml has bits bi i, 
b 21> b 31» b 41- d* 1 ^. h$i . The second column has bits bi2> b 22> b 32» 



b42- an d b52- The third column has bits bi3, b23, b33, b43, and 
b53. The fourth column has bits b^4, b24, b34, b44, and b54- The 
fifth column has bits bi5, b25, b35, b45, and b55. 

In the second step of Fig. 6, the logical operation unit 32 sets 
a movable scanning window in the first matrix Ml which covers 2- 
by-2 neighboring elements (bits). Initially, the window is located in 
the uppermost and leftmost position within the first matrix Ml, 
covering bits b^, h\2, ^>2l' anci b 22- The logical operation unit 32 
executes Exclusive- OR operation among the bits b^, h\2, ^21* 
t>22- The result of the Exclusive-OR operation is a bit en. The 
logical operation unit 32 places the bit c \ \ in the first-row first- 
column element position within the second matrix M2. As will be 
made clear later, the second matrix M2 has 4 rows by 4 columns. 
The window is shifted rightward from the initial position by one 
column. The resultant window covers bits bx2. k±3> D 22> and b23- 
The logical operation unit 32 executes Exclusive-OR operation 
among the bits b\2, ^13, ^>22> and b23- The result of the Exclusive- 
OR operation is a bit ci 2- The logical operation unit 32 places the 
bit ci2 in th e first- row second-column element position within the 
second matrix M2. During a subsequent stage, signal processing 
similar to the above-mentioned signal processing is iterated. 
Specifically, the window is shifted rightward one column by one 
column, and Exclusive-OR operation is executed among four bits in 
the window each time the window is in one position. A bit being 
the result of each Exclusive-OR operation is placed in a 
corresponding element position within the second matrix M2. The 
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wlndow reaches the uppermost and rightmost position. When 
signal processing related to the window in the uppermost and 
rightmost position is completed, the first row in the second matrix 
M2 is filled with bits c\i, c\2, 013, and C14. 
5 Then, the window is shifted to the second-uppermost and 

leftmost position within the first matrix Ml, covering bits b2i, ^22' 
b3i , and b32- The logical operation unit 32 executes Exclusive-OR 
operation among the bits b2i, b22> ^31, and b32- The result of the 
Exclusive-OR operation is a bit C2 1 . The logical operation unit 32 
1 0 places the bit C21 in the second-row first-column element position 
within the second matrix M2. The window is shifted rightward by 
one column. The resultant window covers bits b22» t>23> t>32> axi( -^ 
b33. The logical operation unit 32 executes Exclusive-OR operation 
among the bits b22. t>23' b32, and b33. The result of the Exclusive- 

1 5 OR operation is a bit C22- The logical operation unit 32 places the 

bit C22 in the second-row second-column element position within 
the second matrix M2. During a subsequent stage, signal processing 
similar to the above-mentioned signal processing is iterated. 
Specifically, the window is shifted rightward one column by one 

2 0 column, and Exclusive-OR operation is executed among four bits in 

the window each time the window is in one position. A bit being 
the result of each Exclusive-OR operation is placed in a 
corresponding element position within the second matrix M2. The 
window reaches the second-uppermost and rightmost position. 
2 5 When signal processing related to the window in the second- 
uppermost and rightmost position is completed, the second row in 
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the second matrix M2 is filled with bits C21, C22> c 23> an ^ C24. 

Then, the window is shifted to the third-uppermost and 
leftmost position within the first matrix Ml. During a subsequent 
stage, signal processing similar to the above-mentioned signal 
5 processing is iterated. Specifically, the window is shifted rightward 
one column by one column, and Exclusive-OR operation is executed 
among four bits in the window each time the window is in one 
position. A bit being the result of each Exclusive-OR operation is 
placed in a corresponding element position within the second 

1 0 matrix M2. Finally, the window reaches the lowermost and 

rightmost position. When processes related to the window in the 
lowermost and rightmost position are completed, the second matrix 
M2 is filled with bits c\i, ci 2 > C13, 014, C21, C22> c 23> c 24> c 31> 
c 32> c 33> c 34> c 41> c 42> c 43> C44. m this way, the second step 

15 of Fig. 6 compresses the first matrix Ml into the second matrix M2. 
In other words, the first step compresses 25 bits (one block) into 
16 bits. In the second step of Fig. 6, the logical operation unit 32 
rearranges the bits of the second matrix M2 into a fifth bit 
sequence, that is, a sequence of bits en, ci2- c 13> c 14> c 21> c 22> 

20 c 2 3, c 2 4, c 31 , c 32 , c 33 , c 34 , c 41 , c 42 , c 43 , and c 44 . The logical 
operation unit 32 outputs the fifth bit sequence as a 16-bit portion 
of a first-key signal (a signal representative of a first key Kl). In this 
way, the second step of Fig. 6 compresses the fourth bit sequence 
(the 25-bit sequence) into a 16-bit portion of the first-key signal. 

2 5 The second step of Fig. 6 executes the previously-mentioned 

signal processing for each of the 25-bit blocks (the fourth bit 
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sequences). In other words, the second step repeats the signal 
processing a predetermined number of times which is equal to the 
number of the 25-bit blocks (the fourth bit sequences). The 
repetition of the signal processing completes the first-key signal. In 
5 the case where the number of the 25-bit blocks (the fourth bit 
sequences) is equal to 4, the first-key signal is formed by 64 bits. 

It should be noted that the logical operation unit 32 may 
output only one fifth bit sequence as the whole of the first-key 
signal. 

1 0 Each Exclusive-OR operation among four bits by, by + i , bi+lj> 

and bj + ij + i in the window is generally expressed as follows. 

cij = b y e b ij+ i e b i+ ij © b i+ i j+ i -(2) 

i, j = 1, 2, 3, 4 

where cij denotes a bit being the result of the Exclusive-OR 

1 5 operation, and © denotes an operator of one unit portion of the 

Exclusive-OR operation. 

Setting the window in the first matrix Ml and shifting the 
window therein mean forming blocks in the first matrix Ml, 
wherein each of the blocks has bits, the number of which is smaller 

2 0 than the number of bits composing the first matrix Ml. Exclusive- 

OR operation among bits in the window means logical operation 
among bits in each of blocks in the first matrix Ml. 

It should be noted that the second step of Fig. 6 may divide 
the third bit sequence generated by the first step into blocks each 
2 5 having successive bits, the number of which differs from 25. In this 
case, the number of bits composing one fourth bit sequence differs 
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from 25. Also, the second step may rearrange the bits of each 
fourth bit sequence (each 25-bit sequence) in the first matrix Ml 
according to a predetermined arrangement rule different from the 
previously-mentioned arrangement rule. The second step may 
5 execute OR operation or AND operation among four bits in the 
window instead of Exclusive-OR operation. 

As understood from the previous description, the calculators 
or the key generators 3A and 10A implement 8-to-4 bit data 
reduction (compression) in the first step, and implement 25-to-16 
1 0 bit data reduction (compression) in the second step. The 

calculators 3A and 10A may process and compress selected one or 
ones of 8-bit blocks of the first-key base information. In this case, 
the rate of the compression of the first-key base information to 
generate the first-key signal can be changed among different values. 

1 5 The first-key base information may have a given number of bits 

which differs from a multiple of 8. In this case, the calculators 3A 
and 10A divide the first-key base information into 8-bit blocks and 
one remaining block having bits, the number of which differs from 
8. The calculators 3 A and 10A discard the remaining block. 

2 0 Accordingly, the rate of the compression of the first-key base 

information to generate the first-key signal can be changed among 
various values. Thus, the calculators 3 A and 10A are sufficiently 
flexible regarding a data compression rate. 

The second embodiment of this invention may be modified as 
2 5 follows. Specifically, a modification of the second embodiment of 

this invention implements encryption through "n" stages, where "n" 



denotes a predetermined natural number equal to or greater than 3. 
In the modification, an n-th encryptor encrypts (n-l)-th key base 
information according to a predetermined one-way function. 



